Dave Brockman dave at brockmans.com
Fri Dec 28 15:51:49 UTC 2012

On 12/27/2012 8:15 PM, David White wrote:
> I'm very familiar with SPF, DKIM, and DMARC records (in DNS), but
> while these mechanisms provide a way for receiving mail servers to
> reliably identify whether or not the incoming message came from the
> legitimate sender, it seems to me that this doesn't provide a
> reliable way to reliably determine whether or not the message was
> modified in transit.

SPF and DKIM (DMARC is just a policy using the first two) do not
reliably indicate anything about the sender.  They verify the server
sending the mail is "approved" (in SPF case) or signed some subset of
the message content + headers (DKIM).  That might give you some server
+ domain relationship information, but it gives you absolutely nothing
as far as sender verification/validation.  If you want to verify
message content was not modified, a GPG signature can give you that,
but the other end has to be running GPG as well.


